| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826879.2364
Process32FirstW
|
process_name:
[System Process]
snapshot_handle:
0x00000140
process_identifier:
0
|
success
|
1 |
0
|
1619826879.2674
Process32NextW
|
process_name:
System
snapshot_handle:
0x00000140
process_identifier:
4
|
success
|
1 |
0
|
1619826879.2834
Process32NextW
|
process_name:
smss.exe
snapshot_handle:
0x00000140
process_identifier:
276
|
success
|
1 |
0
|
1619826879.2994
Process32NextW
|
process_name:
csrss.exe
snapshot_handle:
0x00000140
process_identifier:
372
|
success
|
1 |
0
|
1619826879.3144
Process32NextW
|
process_name:
csrss.exe
snapshot_handle:
0x00000140
process_identifier:
424
|
success
|
1 |
0
|
1619826879.3304
Process32NextW
|
process_name:
wininit.exe
snapshot_handle:
0x00000140
process_identifier:
432
|
success
|
1 |
0
|
1619826879.3464
Process32NextW
|
process_name:
services.exe
snapshot_handle:
0x00000140
process_identifier:
476
|
success
|
1 |
0
|
1619826879.3614
Process32NextW
|
process_name:
winlogon.exe
snapshot_handle:
0x00000140
process_identifier:
508
|
success
|
1 |
0
|
1619826879.3774
Process32NextW
|
process_name:
lsass.exe
snapshot_handle:
0x00000140
process_identifier:
536
|
success
|
1 |
0
|
1619826879.3924
Process32NextW
|
process_name:
lsm.exe
snapshot_handle:
0x00000140
process_identifier:
544
|
success
|
1 |
0
|
1619826879.4084
Process32NextW
|
process_name:
svchost.exe
snapshot_handle:
0x00000140
process_identifier:
656
|
success
|
1 |
0
|
1619826879.4244
Process32NextW
|
process_name:
VBoxService.exe
snapshot_handle:
0x00000140
process_identifier:
720
|
success
|
1 |
0
|
1619826879.4394
Process32NextW
|
process_name:
svchost.exe
snapshot_handle:
0x00000140
process_identifier:
788
|
success
|
1 |
0
|
1619826879.4554
Process32NextW
|
process_name:
svchost.exe
snapshot_handle:
0x00000140
process_identifier:
868
|
success
|
1 |
0
|
1619826879.4714
Process32NextW
|
process_name:
svchost.exe
snapshot_handle:
0x00000140
process_identifier:
924
|
success
|
1 |
0
|
1619826879.4864
Process32NextW
|
process_name:
svchost.exe
snapshot_handle:
0x00000140
process_identifier:
956
|
success
|
1 |
0
|
1619826879.5024
Process32NextW
|
process_name:
audiodg.exe
snapshot_handle:
0x00000140
process_identifier:
112
|
success
|
1 |
0
|
1619826879.5174
Process32NextW
|
process_name:
svchost.exe
snapshot_handle:
0x00000140
process_identifier:
540
|
success
|
1 |
0
|
1619826879.5334
Process32NextW
|
process_name:
svchost.exe
snapshot_handle:
0x00000140
process_identifier:
1080
|
success
|
1 |
0
|
1619826879.5494
Process32NextW
|
process_name:
spoolsv.exe
snapshot_handle:
0x00000140
process_identifier:
1260
|
success
|
1 |
0
|
1619826879.5644
Process32NextW
|
process_name:
svchost.exe
snapshot_handle:
0x00000140
process_identifier:
1288
|
success
|
1 |
0
|
1619826879.5804
Process32NextW
|
process_name:
taskhost.exe
snapshot_handle:
0x00000140
process_identifier:
1336
|
success
|
1 |
0
|
1619826879.5964
Process32NextW
|
process_name:
dwm.exe
snapshot_handle:
0x00000140
process_identifier:
1384
|
success
|
1 |
0
|
1619826879.6114
Process32NextW
|
process_name:
explorer.exe
snapshot_handle:
0x00000140
process_identifier:
1424
|
success
|
1 |
0
|
1619826879.6274
Process32NextW
|
process_name:
svchost.exe
snapshot_handle:
0x00000140
process_identifier:
1592
|
success
|
1 |
0
|
1619826879.6424
Process32NextW
|
process_name:
svchost.exe
snapshot_handle:
0x00000140
process_identifier:
1980
|
success
|
1 |
0
|
1619826879.6584
Process32NextW
|
process_name:
taskeng.exe
snapshot_handle:
0x00000140
process_identifier:
1240
|
success
|
1 |
0
|
1619826879.6744
Process32NextW
|
process_name:
VBoxTray.exe
snapshot_handle:
0x00000140
process_identifier:
2072
|
success
|
1 |
0
|
1619826879.6894
Process32NextW
|
process_name:
SearchIndexer.exe
snapshot_handle:
0x00000140
process_identifier:
2380
|
success
|
1 |
0
|
1619826879.7054
Process32NextW
|
process_name:
wmpnetwk.exe
snapshot_handle:
0x00000140
process_identifier:
2460
|
success
|
1 |
0
|
1619826879.7214
Process32NextW
|
process_name:
WmiPrvSE.exe
snapshot_handle:
0x00000140
process_identifier:
2672
|
success
|
1 |
0
|
1619826879.7364
Process32NextW
|
process_name:
SearchProtocolHost.exe
snapshot_handle:
0x00000140
process_identifier:
2744
|
success
|
1 |
0
|
1619826879.7524
Process32NextW
|
process_name:
SearchFilterHost.exe
snapshot_handle:
0x00000140
process_identifier:
2784
|
success
|
1 |
0
|
1619826879.7674
Process32NextW
|
process_name:
svchost.exe
snapshot_handle:
0x00000140
process_identifier:
2884
|
success
|
1 |
0
|
1619826879.7834
Process32NextW
|
process_name:
SearchProtocolHost.exe
snapshot_handle:
0x00000140
process_identifier:
2940
|
success
|
1 |
0
|
1619826879.7994
Process32NextW
|
process_name:
pythonw.exe
snapshot_handle:
0x00000140
process_identifier:
2132
|
success
|
1 |
0
|
1619826879.8144
Process32NextW
|
process_name:
pythonw.exe
snapshot_handle:
0x00000140
process_identifier:
1376
|
success
|
1 |
0
|
1619826879.8304
Process32NextW
|
process_name:
dllhost.exe
snapshot_handle:
0x00000140
process_identifier:
3056
|
success
|
1 |
0
|
1619826879.8464
Process32NextW
|
process_name:
taskhost.exe
snapshot_handle:
0x00000140
process_identifier:
2856
|
success
|
1 |
0
|
1619826879.8614
Process32NextW
|
process_name:
sdclt.exe
snapshot_handle:
0x00000140
process_identifier:
2996
|
success
|
1 |
0
|
1619826879.8774
Process32NextW
|
process_name:
wsqmcons.exe
snapshot_handle:
0x00000140
process_identifier:
2424
|
success
|
1 |
0
|
1619826879.8924
Process32NextW
|
process_name:
mobsync.exe
snapshot_handle:
0x00000140
process_identifier:
3064
|
success
|
1 |
0
|
1619826879.9084
Process32NextW
|
process_name:
a7c930732560445a040bf5534d87013e.exe
snapshot_handle:
0x00000140
process_identifier:
368
|
success
|
1 |
0
|
1619826879.9244
Process32NextW
|
process_name:
schtasks.exe
snapshot_handle:
0x00000140
process_identifier:
1912
|
success
|
1 |
0
|
1619826879.9394
Process32NextW
|
process_name:
conhost.exe
snapshot_handle:
0x00000140
process_identifier:
2456
|
success
|
1 |
0
|
1619826901.077751
Process32NextW
|
process_name:
a7c930732560445a040bf5534d87013e.exe
snapshot_handle:
0x00000140
process_identifier:
340
|
success
|
1 |
0
|